The S3 Video, EasySqueezePage, External “Video for Everybody”, Videopack, and 1player plugins for WordPress have an issue that might allow unauthenticated attackers to inject malicious code into pages. This is because the plugins use a vulnerable version of VideoJS and don’t properly filter user input or properly escape output. If a user is tricked into clicking on a link, the malicious code would then execute.